Closed
Bug 272249
Opened 20 years ago
Closed 18 years ago
LXR error reveals server configurations and versions
Categories
(Webtools Graveyard :: MXR, defect)
Tracking
(Not tracked)
RESOLVED
WORKSFORME
People
(Reporter: bulk88, Assigned: bear)
References
()
Details
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0) Build Identifier: Went to thios page, got an error. It reveals under the hood stuff about the site, and what perl version is runs. The version (5.6.x) seems old to me (maybe b/c I am a newbie), so it could be a security risk. Reproducible: Always Steps to Reproduce: 1. goto http://lxr.mozilla.org/seamonkey/ident?i=this 2. 3.
Comment 1•20 years ago
|
||
This is not a bug. I'm quite sure that the server intentionally advertises this information. -> Myk.
Assignee: mitchell → myk
Component: Miscellaneous → Server Operations
Comment 2•20 years ago
|
||
Confirming the error message. Not sure this is serious problem requiring the confidential flags, but switching from the general security flag to the more appropriate webtools security flag.
Group: security → webtools-security
Status: UNCONFIRMED → NEW
Ever confirmed: true
Summary: reveals server configurations and versions → LXR error reveals server configurations and versions
Comment 3•20 years ago
|
||
It's common knowledge that we run RHEL, and those are the standard paths for those files on RHEL, so it's not exposing any information anyone wouldn't know anyway. That said, I'm not a big fan of the whole "security by obscurity" thing, we're better off making sure the system can't be broken into for them to have the chance to use it.
Assignee: myk → leaf
Component: Server Operations → LXR
Product: mozilla.org → Webtools
QA Contact: mitchell → timeless
Comment 4•20 years ago
|
||
(moved to LXR because the fact those error messages are showing up is an LXR bug)
Updated•18 years ago
|
QA Contact: timeless → lxr
Comment 5•18 years ago
|
||
I don't see anything server-related when I go to http://lxr.mozilla.org/seamonkey/ident?i=this Is this still an issue?
Assignee: leaf → bear
Comment 6•18 years ago
|
||
This error isn't showing up any more, and this isn't really a security issue. Closing out.
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → WORKSFORME
Updated•18 years ago
|
Group: webtools-security
Updated•18 years ago
|
Group: webtools-security
Updated•18 years ago
|
Group: webtools-security
Updated•18 years ago
|
Group: webtools-security
Updated•18 years ago
|
Group: webtools-security
Updated•18 years ago
|
Group: webtools-security
Updated•18 years ago
|
Group: webtools-security
Updated•5 years ago
|
Product: Webtools → Webtools Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•